MEDIUM6.5
GHSA-2mj3-vfvx-fc43
Moby Race Condition vulnerability
Quick fix
GHSA-2mj3-vfvx-fc43 — github.com/moby/moby: upgrade to the fixed version with the command below.
go get github.com/moby/moby@v26.0.0Details
moby v25.0.5 is affected by a Race Condition in builder/builder-next/adapters/snapshot/layer.go. The vulnerability could be used to trigger concurrent builds that call the EnsureLayer function resulting in resource leaks/exhaustion.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2024-36621[ADVISORY]
- https://github.com/moby/moby/commit/37545cc644344dcb576cba67eb7b6f51a463d31e[WEB]
- https://gist.github.com/1047524396/5d44459edab5fafcdf86b43909b81135[WEB]
- https://github.com/advisories/GHSA-2mj3-vfvx-fc43[ADVISORY]
- https://github.com/moby/moby[PACKAGE]
- https://github.com/moby/moby/blob/v25.0.5/builder/builder-next/adapters/snapshot/layer.go#L24[WEB]